Repository navigation
ci: reject retired repository links in active documentation - #524
Conversation
@coderabbitai full review |
✅ Action performedFull review finished. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 37 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (8)
🧰 Additional context used📓 Path-based instructions (1)Source excerpt: **Least-privilege permissions.**📄 CodeRabbit inference engine (AGENTS.md) Files:
🔇 Additional comments (2)
📝 WalkthroughWalkthroughThe change adds a versioned configuration for scanning retired repository links in README.md and AGENTS.md. CI runs the pinned validator and checks its scan result, its response to a seeded retired link, and its handling of missing configuration. The required-check aggregator now includes the validator job. Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to The retired-link guard is configured for README.md and AGENTS.md and included in required checks. No merge-blocking issue was identified. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Linked Issues checkExplanation Issue
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
@coderabbitai full review |
|
devantler
left a comment
There was a problem hiding this comment.
🤖 Generated by the Agentic Engineer
Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)
Reviewed commit: 3205d34
Provider receipts were freshly authenticated at 2026-10-05T10:43:07Z; direct current-PR reviews, conversation comments, inline comments, threads and complete check-run pages were read.
- CodeRabbit: this PR's exact-head request was rate limited at 2026-10-05T10:28:43Z, with a 37-minute recovery window ending 2026-10-05T11:05:43Z. Provider receipt.
- Codex: the applicable review account reached its code-review usage limit at 2026-10-05T08:40:17Z; the authenticated response states no reset and requires account capacity to recover. Provider receipt.
- Cursor Bugbot: the applicable review user or team hit a usage or spend limit at 2026-10-05T05:09:57Z; the authenticated response states no reset and requires a user or team administrator to restore capacity. Provider receipt.
Verdict: no P0/P1 findings
Independently reviewed both changed files and the immutable bd0035dd8f41fcf1459b878882b8897443f8dc59 validator runtime. The explicit opt-in, scoped documentation configuration, complete-scan output, read-only job and required-check aggregation preserve the existing validation and publication boundaries.
The actual inline refusal script was extracted from this head and executed with the pinned source. The clean consumer scan examined both documents with zero exceptions or retired links; the seeded README link produced exit 1 with its expected diagnostic, and missing configuration produced exit 2. Workflow lint and diff checks passed. Local execution used Go 1.27.1; hosted execution uses the action's declared Go 1.26.8.
CodeRabbit's linked-issue assessment remains inconclusive because native CI at this head and postmerge main verification are still pending. Those acceptance requirements remain in force; this review supplies no CI or merge clearance.
Native evaluation verified for PR head
The negative controls execute the released CLI; this job does not invoke separate negative action steps or test their action outputs. Merged-main verification remains pending. |
Why
Active documentation can silently send readers to a retired workflow repository because CI does not check those links.
What
Add the shared read-only link guard to required CI, with controls proving that retired links and incomplete scans are rejected.
Fixes #523